Yinhao Xiao

dblp:208/0865 · DBLP profile ↗
← Back
19ranked-venue papers
5as first author
11since 2021 · last 2025
0000-0002-9871-9552ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 11 · 2 first-author · 4 since 2021Security and privacy · 5 · 2 first-author · 5 since 2021Systems, architecture and hardware · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2025 FlipBoost: Strengthening Backdoors in LoRA-Tuned Language Models via Bit-Level Injection
abstract
Backdoor attacks pose a significant security threat to large language models (LLMs), allowing adversaries to implant malicious behaviors that are triggered by specific inputs. While existing fine-tuning methods often produce unstable backdoors, their reliability remains limited in real-world scenarios. We propose FlipBoost, a reward-guided bit-level attack targeting LoRA-fine-tuned LLMs to amplify the effectiveness of pre-injected backdoor triggers. FlipBoost identifies and injects a minimal set of high-impact bit flips into LoRA adapter parameters based on target logit gain. Without requiring access to training data or model gradients, our method elevates the trigger activation rate from 10% to 91% using only 15-bit modifications. Experiments on GPT-2 with DailyDialog-style prompts validate the attack’s efficiency and precision. FlipBoost exposes a new vector for post-tuning exploitation in parameter-efficient LLMs and highlights the urgent need for integrity verification and adaptive defense mechanisms.
Haoyang Peng, Minghui Xu 0001, Yinhao Xiao
MASS3
2024 TBAC: A Tokoin-Based Accountable Access Control Scheme for the Internet of Things
abstract
Overprivilege Attack, a widely reported phenomenon in IoT that accesses unauthorized or excessive resources, is notoriously hard to prevent, trace and mitigate. In this paper, we propose TBAC, a Tokoin-Based Access Control model enabled by blockchain and Trusted Execution Environment (TEE) technologies, to offer fine-grained access control and strong auditability for IoT. TBAC materializes the virtual access power into a definite-amount, secure and accountable cryptographic coin, termed “tokoin” (token+coin), and manages it using atomic and accountable state-transition functions in a blockchain. A tokoin carries a fine-grained policy defined by the resource owner to specify the requirements to be satisfied before an access is granted, and the behavioral constraints that describe the correct procedure to follow during access. The strong-auditability is achieved with blockchain and a TEE-enabled trusted access control object (TACO) to ensure that all access activities are securely monitored and auditable. We prototype TBAC by implementing all its functions with well-studied cryptographic primitives over different blockchain platforms, building a TACO on top of the ARM Cortex-M33 TEE microcontroller, and constructing a user-friendly APP for regular users. A case study is finally presented to demonstrate how TBAC is employed to enable autonomous and secure in-home cargo delivery.
Chun-Chi Liu, Minghui Xu 0001, Hechuan Guo, Xiuzhen Cheng, Yinhao Xiao, Dongxiao Yu, Bei Gong, Arkady Yerukhimovich, Shengling Wang 0001, Weifeng Lyu
IEEE Trans. Mob. Comput.5
2023 DeepVulSeeker: A novel vulnerability identification framework via code graph structure and pre-training mechanism
Jin Wang 0026, Shuwen Zhong, Yinhao Xiao
Future Gener. Comput. Syst.4
2023 A novel GPU based Geo-Location Inference Attack on WebGL framework
abstract
In the past few years, graphics processing units (GPUs) have become an indispensable part of modern computer systems, not only for graphics rendering but also for intensive parallel computing. Given that many tasks running on GPUs contain sensitive information, security concerns have been raised, especially about potential GPU information leakage. Previous works have shown such concerns by showing that attackers can use GPU memory allocations or performance counters to measure victim side effects (Naghibijouybari et al., 2018). However, such an attack has a critical drawback that it requires a victim to install desktop applications or mobile apps yielding it uneasy to be deployed in the real world. In this paper, we solve this drawback by proposing a novel GPU-based side-channel Geo-Privacy inference attack on the WebGL framework, namely, GLINT (stands for Geo-Location Inference Attack). GLINT merely utilizes a lightweight browser extension to measure the time elapsed to render a sequence of frames on well-known map websites, e.g., Google Maps, or Baidu Maps. The measured stream of time series is then employed to infer geologically privacy-sensitive information, such as a search on a specific location. Upon retrieving the stream, we propose a novel online segmentation algorithm for streaming data to determine the start and end points of privacy-sensitive time series. We then combine the DTW algorithm and KNN algorithm on these series to conclude the final inference on a user’s geo-location privacy. We conducted real-world experiments to testify our attack. The experiments show that GeoInfer can correctly infer more than 83% of user searches regardless of the locations and map websites, meaning that our Geo-Privacy inference attack is accurate, practical, and robust. To counter this attack, we implemented a defense strategy based on Differential Privacy to hinder obtaining accurate rendering data. We found that this defense mechanism managed to reduce the average accuracy of the attack model by more than 70%, indicating that the attack was no longer effective. We have fully implemented GLINT and open-sourced it for future follow-up research.
Weixian Mai, Yinhao Xiao
High Confid. Comput.2
2023 JFinder: A novel architecture for java vulnerability identification based quad self-attention and pre-training mechanism
abstract
Software vulnerabilities pose significant risks to computer systems, impacting our daily lives, productivity, and even our health. Identifying and addressing security vulnerabilities in a timely manner is crucial to prevent hacking and data breaches. Unfortunately, current vulnerability identification methods, including classical and deep learning-based approaches, exhibit critical drawbacks that prevent them from meeting the demands of the contemporary software industry. To tackle these issues, we present JFinder, a novel architecture for Java vulnerability identification that leverages quad self-attention and pre-training mechanisms to combine structural information and semantic representations. Experimental results demonstrate that JFinder outperforms all baseline methods, achieving an accuracy of 0.97 on the CWE dataset and an F1 score of 0.84 on the PROMISE dataset. Furthermore, a case study reveals that JFinder can accurately identify four cases of vulnerabilities after patching.
Jin Wang 0026, Zishan Huang, Yinhao Xiao
High Confid. Comput.4
2023 I Know Your Social Network Accounts: A Novel Attack Architecture for Device-Identity Association
abstract
Online social networks revolutionize the way people interact with each other. When various social network information aggregates over time, a rich online profile of the user is formed. Owing to the various features provided by mobile devices, a user's online social activities are tightly tied to his phone, and are conveniently, sometimes unnecessarily, available to social networks. In this article, we propose a novel attack architecture to show that attackers can infer a user's social network identities behind a mobile device through new dimensions. Specifically, we first developed a correlation between a user's device system states and the social network events, which leverage multiple mechanisms such as the learning-based memory regression model, to infer the possible accounts of the user in the social network app. Then we exploited the social network to social network correlation, via which we correlated information across different social networks, to identify the accounts of the target user. We implemented and evaluated these attacks on three popular social networks, and the results corroborate the effectiveness of our design.
Yinhao Xiao, Xiuzhen Cheng, Shengling Wang 0001, Zhenkai Liang
IEEE Trans. Dependable Secur. Comput.1
2023 CommandFence: A Novel Digital-Twin-Based Preventive Framework for Securing Smart Home Systems
abstract
Smart home systems are both technologically and economically advancing rapidly. As people become gradually inalienable to smart home infrastructures, their security conditions are getting more and more closely tied to everyone's privacy and safety. In this paper, we consider smart apps, either malicious ones with evil intentions or benign ones with logic errors, that can cause property loss or even physical sufferings to the user when being executed in a smart home environment and interacting with human activities and environmental changes. Unfortunately, current preventive measures rely on permission-based access control, failing to provide ideal protections against such threats due to the nature of their rigid designs. In this paper, we propose CommandFence, a novel digital-twin-based security framework that adopts a fundamentally new concept of protecting the smart home system by letting any sequence of app commands to be executed in a virtual smart home system, in which a deep-q network (DQN) is used to predict if the sequence could lead to a risky consequence. CommandFence is composed of an Interposition Layer to interpose app commands and an Emulation Layer to figure out whether they can cause any risky smart home state if correlating with possible human activities and environmental changes. We fully implemented our CommandFence implementation and tested against 553 official SmartApps on the Samsung SmartThings platform and successfully identified 34 potentially dangerous ones, with 31 of them reported to be problematicAuthor: Please provide index terms/keywords for your article. To download the IEEE Taxonomy go tohttp://www.ieee.org/documents/taxonomy_v101.pdf?> the first time to our best knowledge. Moreover, We tested our CommandFence on the 10 malicious SmartApps created by Jiaet al.2017, and successfully identified 7 of them as risky, with the missed ones actually only causing smartphone information leak (not harmful to the smart home system). We also tested CommandFence against the 17 benign SmartApps with logic errors developed by Celiket al.2017, and achieved a 100% accuracy. Our experimental studies indicate that adopting CommandFence incurs a neglectable overhead of 0.1675 seconds.
Yinhao Xiao, Qin Hu 0001, Xiuzhen Cheng, Bei Gong, Jiguo Yu
IEEE Trans. Dependable Secur. Comput.1
2022 Multi-view Pre-trained Model for Code Vulnerability Identification
Xuxiang Jiang, Yinhao Xiao, Jun Wang 0006, Wei Zhang 0056
WASA (3)2
2022 Transaction pricing mechanism design and assessment for blockchain
abstract
The importance of transaction fees in maintaining blockchain security and sustainability has been confirmed by extensive research, although they are not mandatory in most current blockchain systems. To enhance blockchain in the long term, it is crucial to design effective transaction pricing mechanisms. Different from the existing schemes based on auctions with more consideration about the profit of miners, we resort to game theory and propose a correlated equilibrium based transaction pricing mechanism through solving a pricing game among users with transactions, which can achieve both the individual and global optimum. To avoid the computational complexity exponentially increasing with the number of transactions, we further improve the game-theoretic solution with an approximate algorithm, which can derive almost the same results as the original one but costs significantly reduced time. We also propose a truthful assessment model for pricing mechanism to collect the feedback of users regarding the price suggestion. Extensive experimental results demonstrate the effectiveness and efficiency of our proposed mechanism.
Zhilin Wang, Qin Hu 0001, Yinhao Xiao
High Confid. Comput.4
2021 A differential game view of antagonistic dynamics for cybersecurity
Shengling Wang 0001, Yu Pu, Yinhao Xiao
Comput. Networks5
2021 Design of cloud computing task offloading algorithm based on dynamic multi-objective evolution
Su Hu, Yinhao Xiao
Future Gener. Comput. Syst.2
2020 Correlated Participation Decision Making for Federated Edge Learning
abstract
Driven by the sheer amount of data generated at the network edge and improved computation capabilities of mobile devices, federated edge learning (FEL) emerges as a novel paradigm to achieve edge intelligence with a favorable property of protecting privacy for data generators, i.e., edge devices. However, limited computation and communication resources at the edge make it challenging to execute FEL cost-efficiently in practice. Faced with this challenge, lots of existing work focus on the optimization control during the learning process. However, these research take no precaution in terms of composing the FEL system given heterogeneous candidate devices, which can severely impact the implementation performance. To solve this issue, we define a participation game to capture the dependent but competitive relationships among edge devices with respect to making decisions on whether to participate in a round of FEL. Then we propose a correlated equilibrium based participation decision making strategy to achieve individual rationality and global profit maximization at the same time, which can maintain the efficiency and sustainability of FEL in the long term. Furthermore, we devise an improved method with polynomial computational cost to enhance the scalability of the game-theoretic solution. The performance of our proposed scheme is evaluated through extensive experimental results.
Qin Hu 0001, Feng Li 0001, Xukai Zou, Yinhao Xiao
GLOBECOM4
2020 BC-SABE: Blockchain-Aided Searchable Attribute-Based Encryption for Cloud-IoT
abstract
The Internet of Things (IoT) changed our lives with huge amounts of data production. Due to source-limited IoT devices, one of the best ways to process the data is cloud storage. However, a series of security and privacy issues arise, such as illegal data access, data tampering, and privacy leak. Though symmetric encryption can guarantee data confidentiality, it cannot realize fine-grained data sharing and searching. The keyword-based searchable attribute-based encryption (KSABE) can achieve data confidentiality and fine-grained access control. More importantly, it realizes a keyword-based search for data users. However, the heavy decryption computation burden and the management of massive user keys appear when implementing attribute-based encryption schemes to IoT. Therefore, this article proposes a blockchain-aided searchable attribute-based encryption (BC-SABE) with efficient revocation and decryption, where the traditional centralized server is replaced with a decentralized blockchain system being in charge of the threshold parameter generation, key management, and user revocation. All revocation tasks are done by the blockchain and it is on longer necessary for ciphertext reencryption and key update. Moreover, users utilize the coalition blockchain to generate partial tokens. Besides, the cloud server contained in our scheme not only stores the massive encrypted data but also performs search and predecryption for users who only require one exponentiation in the group G to decrypt fully. Security analyses prove that our scheme realizes the security under the chosen plaintext attack and the chosen keyword attack. Simulations show that the decryption and token generation cost of our scheme are preferable.
Suhui Liu, Jiguo Yu, Yinhao Xiao, Zhiguo Wan, Shengling Wang 0001, Biwei Yan
IEEE Internet Things J.3
2020 Queuing Without Patience: A Novel Transaction Selection Mechanism in Blockchain for IoT Enhancement
abstract
There is evidence that blockchain plays a crucial role in the Internet of Things (IoT)-based implementation due to its transparency, traceability, and immutability, in which the participants are incentivized to behave authentically and precisely for rewards. Despite the domination of subsidy in reward, the decrease of the mining rate and the imperativeness of fees make the fee market become a pivotal role to motivate miners in the blockchain. However, the current mechanism for selecting transactions into a block poses a risk to the stability of the system, which stems from the vicious competition of users and the insufficient incentives of miners. In this article, we propose a novel transaction selection mechanism by leveraging the Lyapunov optimization and large deviation theory. This article is: 1) fair because the proposed mechanism is not single-factor dominated, both personal utility of the miner and overall utility of the system are taken into account; 2) sustainable since miners are incentivized greatly to guarantee the mining behavior; and 3) robust. The analysis based on the large deviation theory enhances the robustness of the blockchain. To the best of our knowledge, we are the first to consider both miner's benefit as well as system benefit to establish a better fee market in the blockchain for IoT enhancement. Our theoretical analyses and simulation results demonstrate the effectiveness of the proposed mechanism.
Shengling Wang 0001, Yinhao Xiao
IEEE Internet Things J.3
2020 HomeShield: A Credential-Less Authentication Framework for Smart Home Systems
abstract
Smart home systems have become more and more prevailent in recent years. On the one hand, they make our everyday life more convenient; on the other hand, they suffer from the two notorious security problems, namely, the open-port problem and the overprivilege problem, making their security situations extremely worrying and uncheerful. In this article, we proposed HomeShield, a novel credential-less authentication framework to shield smart home systems by effectively defending against the attacks resulted from these two security problems without the need for sensitive credentials. We further detailed an implementation of HomeShield based on the side channels that are publicly available in Android smartphones serving as controllers of smart home systems and presented its workflow in protecting against various attacks caused by the open-port and overprivilege problems. Finally, we tested our HomeShield implementation on a real-world smart home system and considered four threat models that cover basically all practical attacks, including Mirai and its variants. We also considered the effectiveness of our HomeShield implementation on the SmartApps of the Samsung SmartThings platform, which also suffers from the open-port and overprivilege problems, even though its overprivilege issue has been extensively studied by the recently proposed works, such as ContexIoT and SmartAuth. The evaluation results indicate that our HomeShield realization can successfully defend against over 90% attack trials with an average latency of less than 1 s.
Yinhao Xiao, Chun-Chi Liu, Arwa Alrawais, Molka Rekik, Zhiguang Shan
IEEE Internet Things J.1
2019 NormaChain: A Blockchain-Based Normalized Autonomous Transaction Settlement System for IoT-Based E-Commerce
abstract
Internet of Things (IoT)-based E-commerce is a new business model that relies on autonomous transaction management on IoT-devices. The management system toward IoT-based E-commerce demands autonomy, lightweight, and legitimacy. As blockchain is an innovative technology that is competent in governing the decentralized network, we adopt it to design the autonomous transaction management system on IoT E-commerce. However, current blockchain solutions, most namely cryptocurrencies, have fatal drawbacks of nonsupervisability and huge computational overhead, and hence cannot be directly applied on IoT-based E-commerce. In this paper, we propose NormaChain, a blockchain-based normalized autonomous transaction settlement system for IoT-based E-commerce. By designing a special three-layer sharding blockchain network, we can significantly increase transaction efficiency and system scalability. Additionally, by designing an innovative decentralized public key searchable encryption scheme (decentralized public key encryption with keyword search (PEKS) scheme), we can uncover illegal and criminal transactions and achieve crime traceability. Our new decentralized PEKS scheme cryptographically eliminates the dependence of a trusted central authority in the original PEKS scheme and instead expands it to a fully decentralized governance, which distributes the supervision power equally among all parties. More importantly, by proving NormaChain is secure against chosen ciphertext attacks and against the stealing of the secret key, we show that NormaChain prevents a legitimate user’s privacy from being violated by banks, supervisors or malicious adversaries. Finally, we deliver the NormaChain system with design details and full implementations. Experiments show that the average transaction-per-second on IoT devices is around 113, and the supervision accuracy is 100% when proper target illegal keywords are provided.
Chun-Chi Liu, Yinhao Xiao, Vishesh Javangula, Qin Hu 0001, Shengling Wang 0001, Xiuzhen Cheng
IEEE Internet Things J.2
2019 I Can See Your Brain: Investigating Home-Use Electroencephalography System Security
abstract
Health-related Internet of Things (IoT) devices are becoming more popular in recent years. On the one hand, users can access information of their health conditions more conveniently; on the other hand, they are exposed to new security risks. In this paper, we presented, to the best of our knowledge, the first in-depth security analysis on home-use electroencephalography (EEG) IoT devices. Our key contributions are twofold. First, we reverse-engineered the home-use EEG system framework via which we identified the design and implementation flaws. By exploiting these flaws, we developed two sets of novel easy-to-exploit PoC attacks, which consist of four remote attacks and one proximate attack. In a remote attack, an attacker can steal a user's brain wave data through a carefully crafted program while in the proximate attack, the attacker can steal a victim's brain wave data over-the-air without accessing the victim's device on any sense when he is close to the victim. As a result, all the 156 brain-computer interface (BCI) apps in the NeuroSky App store are vulnerable to the proximate attack. We also discovered that all the 31 free apps in the NeuroSky App store are vulnerable to at least one remote attack. Second, we proposed a novel deep learning model of a joint recurrent convolutional neural network (RCNN) to infer a user's activities based on the reduced-featured EEG data stolen from the home-use EEG IoT devices, and our evaluation over the real-world EEG data indicates that the inference accuracy of the proposed RCNN is can reach 70.55%.
Yinhao Xiao, Xiuzhen Cheng, Jiguo Yu, Zhenkai Liang, Zhi Tian
IEEE Internet Things J.1
2019 Edge Computing Security: State of the Art and Challenges
abstract
The rapid developments of the Internet of Things (IoT) and smart mobile devices in recent years have been dramatically incentivizing the advancement of edge computing. On the one hand, edge computing has provided a great assistance for lightweight devices to accomplish complicated tasks in an efficient way; on the other hand, its hasty development leads to the neglection of security threats to a large extent in edge computing platforms and their enabled applications. In this paper, we provide a comprehensive survey on the most influential and basic attacks as well as the corresponding defense mechanisms that have edge computing specific characteristics and can be practically applied to real-world edge computing systems. More specifically, we focus on the following four types of attacks that account for 82% of the edge computing attacks recently reported by Statista: distributed denial of service attacks, side-channel attacks, malware injection attacks, and authentication and authorization attacks. We also analyze the root causes of these attacks, present the status quo and grand challenges in edge computing security, and propose future research directions.
Yinhao Xiao, Chun-Chi Liu, Xiuzhen Cheng, Jiguo Yu, Weifeng Lv
Proc. IEEE1
2018 A Novel Graph-based Mechanism for Identifying Traffic Vulnerabilities in Smart Home IoT
abstract
Smart home IoT devices have been more prevalent than ever before but the relevant security considerations fail to keep up with due to device and technology heterogeneity and resource constraints, making IoT systems susceptible to various attacks. In this paper, we propose a novel graph-based mechanism to identify the vulnerabilities in communication of IoT devices for smart home systems. Our approach takes one or more packet capture files as inputs to construct a traffic graph by passing the captured messages, identify the correlated subgraphs by examining the attribute-value pairs associated with each message, and then quantify their vulnerabilities based on the sensitivity levels of different keywords. To test the effectiveness of our approach, we setup a smart home system that can control a smart bulb LB100 via either the smartphone APP for LB100 or the Google Home speaker. We collected and analyzed 58,714 messages and exploited 6 vulnerable correlated sub graphs, based on which we implemented 6 attack cases that can be easily reproduced by attackers with little knowledge of IoT. This study is novel as our approach takes only the collected traffic files as inputs without requiring the knowledge of the device firmware while being able to identify new vulnerabilities. With this approach, we won the third prize out of 20 teams in a hacking competition.
Yinhao Xiao, Jiguo Yu, Xiuzhen Cheng, Zhenkai Liang, Zhiguo Wan
INFOCOM2